The cLabs team proposes to update the hotfix approval mechanism to use the Security Council multisig. This will replace the previous system, which relied on a quorum of elected validators, with a more agile and secure governance layer for critical upgrades. This CGP aims to execute a governance transaction that adds the Security Council multisig address to the Celo Governance contract. This change will enable the new council to approve hotfixes as soon as the migration completes.
With Celo’s transition to an L2 architecture, we are also re-evaluating core governance mechanisms for responsiveness and security. The hotfix process is crucial for protecting the protocol against urgent vulnerabilities. The dedicated Security Council operating via a multisig wallet allows for faster response times and more flexible coordination, especially in high-severity scenarios.
Proposed Change: Add the Security Council multisig address to the Governance contract to authorize the new Security Council to approve and execute hotfixes post-migration. The actual multisig deployment is planned for March 26, 2025, and its address will be finalized at that time.
0x51a3a77baF58fef0309452CeaCB09221e556f223
)Use the cli to check only the security.
The Security Council must be trusted to act responsibly and only in emergency situations. Governance may need to revisit the multisig’s composition or powers if it becomes a centralization risk. Proper deployment and management of the multisig are critical to avoid misconfigurations or delays in future emergency actions.